34296Third-party advisory
http://secunia.com/advisories/34296 CVE-2008-4610
MPlayer - '.AAC' File Handling Denial of Service
Record summary
CVE-2008-4610 has a selected CVSS score of 5.0; EIP currently links 2 catalogued exploits.
Description
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBMPlayer - '.AAC' File Handling Denial of ServiceExploitDB exploitby Hanno BockNot analyzed1 file
ExploitDBMPlayer - '.OGM' File Handling Denial of ServiceExploitDB exploitby Hanno BockNot analyzed1 file
References
4[oss-security] 20081007 CVE request: crashers / potential security risks in mplayermailing list
http://www.openwall.com/lists/oss-security/2008/10/07/1 USN-734-1Vendor advisory
http://www.ubuntu.com/usn/USN-734-1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4610